This repository contains a hand written SQL Lexer that tokenizes SQL queries with a focus on obfuscating and normalization. The lexer is written in Go with no external dependencies. Note This is NOT a SQL parser, it only tokenizes SQL queries.
- 🚀 Fast and lightweight tokenization (not regex based)
- 🔒 Obfuscates sensitive data (e.g. numbers, strings, specific literals like dollar quoted strings in Postgres, etc.)
- 📖 Even works with truncated queries
- 🌐 UTF-8 support
- 🔧 Normalizes obfuscated queries
go get github.com/DataDog/go-sqllexer
# Clone the repository
git clone https://github.com/DataDog/go-sqllexer.git
cd go-sqllexer
# Build the binary
make build
# Or install directly to your PATH
make install
import "github.com/DataDog/go-sqllexer"
func main() {
query := "SELECT * FROM users WHERE id = 1"
lexer := sqllexer.New(query)
for {
token := lexer.Scan()
if token.Type == EOF {
break
}
fmt.Println(token)
}
}
import (
"fmt"
"github.com/DataDog/go-sqllexer"
)
func main() {
query := "SELECT * FROM users WHERE id = 1"
obfuscator := sqllexer.NewObfuscator()
obfuscated := obfuscator.Obfuscate(query)
// "SELECT * FROM users WHERE id = ?"
fmt.Println(obfuscated)
}
import (
"fmt"
"github.com/DataDog/go-sqllexer"
)
func main() {
query := "SELECT * FROM users WHERE id in (?, ?)"
normalizer := sqllexer.NewNormalizer(
WithCollectComments(true),
WithCollectCommands(true),
WithCollectTables(true),
WithKeepSQLAlias(false),
)
normalized, statementMetadata, err := normalizer.Normalize(query)
// "SELECT * FROM users WHERE id in (?)"
fmt.Println(normalized)
}
The sqllexer
binary provides a command-line interface for all the library functionality:
# Show help
sqllexer -help
# Obfuscate SQL from stdin
echo "SELECT * FROM users WHERE id = 1" | sqllexer
# Obfuscate SQL from file
sqllexer -input query.sql -output obfuscated.sql
# Normalize SQL for PostgreSQL
sqllexer -mode normalize -dbms postgresql -input query.sql
# Tokenize SQL
sqllexer -mode tokenize -input query.sql
# Obfuscate with custom options
sqllexer -replace-digits=false -keep-json-path=true -input query.sql
- obfuscate (default): Replace sensitive data with placeholders
- normalize: Normalize SQL queries for consistent formatting
- tokenize: Show all tokens in the SQL query
Use the -dbms
flag to specify the database type:
mssql
- Microsoft SQL Serverpostgresql
- PostgreSQLmysql
- MySQLoracle
- Oraclesnowflake
- Snowflake
go test -v ./...
go test -bench=. -benchmem ./...